Cloud Security & Compliance
Conversational knowledge about security certifications, NCSC principles, compliance frameworks, evidence requirements, and UK government security standards relevant to G-Cloud service providers.
Purpose
Provide instant answers to common questions about security and compliance requirements for G-Cloud without requiring document generation. This covers certifications, frameworks, clearances, and evidence guidance.
When to Use
Activate when users ask about:
- Whether they need a specific certification (ISO 27001, Cyber Essentials, SOC 2, etc.)
- What the NCSC 14 cloud security principles are
- UK GDPR requirements for cloud services
- Security clearance levels and when they apply
- What evidence to provide (and what NOT to provide)
- Certification costs, timelines, and renewal cycles
- NHS DSPT requirements
- AI governance and the AI Playbook
Quick Reference: Key Certifications
| Certification |
G-Cloud Importance |
Validity |
Typical Cost |
| ISO 27001 |
High — expected by most buyers |
3 years (annual surveillance) |
£5K–£50K+ |
| Cyber Essentials |
High — mandatory for personal data |
12 months |
£300–£500 |
| Cyber Essentials Plus |
High — independent verification |
12 months |
£1,500–£5,000 |
| SOC 2 Type II |
Medium-High — sophisticated buyers |
Annual reports |
£20K–£80K |
| CSA STAR |
Medium — cloud-native services |
Varies by level |
Varies |
| PCI DSS |
Required for payment processing |
Annual |
Varies by level |
Quick Reference: NCSC 14 Principles
| # |
Principle |
Category |
| 1 |
Data in transit protection |
Data Protection |
| 2 |
Asset protection and resilience |
Data Protection |
| 3 |
Separation between users |
Separation |
| 4 |
Governance framework |
Governance |
| 5 |
Operational security |
Operations |
| 6 |
Personnel security |
Personnel |
| 7 |
Secure development |
Development |
| 8 |
Supply chain security |
Supply Chain |
| 9 |
Secure user management |
Access |
| 10 |
Identity and authentication |
Access |
| 11 |
External interface protection |
Infrastructure |
| 12 |
Secure service administration |
Administration |
| 13 |
Audit information for users |
Audit |
| 14 |
Secure use of the service |
Usage |
Quick Reference: Security Clearances
| Level |
Typical Use |
Timeline |
| BPSS |
Standard government access |
1–2 weeks |
| CTC |
Airport, defence |
6–8 weeks |
| SC |
OFFICIAL-SENSITIVE data |
6–8 weeks |
| DV |
SECRET classification |
6–12 months |
| eDV |
TOP SECRET classification |
12+ months |
Quick Reference: Evidence to Provide
| Certification |
Provide |
Do NOT Provide |
| ISO 27001 |
Certificate (scope must cover service) |
Full audit reports |
| Cyber Essentials |
Certificate with badge |
Internal assessments |
| SOC 2 |
Management assertion letter |
Full SOC 2 report |
| CSA STAR |
Registry entry link |
Detailed assessment |
| NHS DSPT |
Published status |
Internal toolkit data |
| PCI DSS |
Attestation of Compliance (AOC) |
Pen test findings |
General rule: never provide full audit reports, pen test findings, detailed vulnerability data, internal policy documents, or unredacted contracts.
Answering Questions
When answering security and compliance questions:
- Check the quick reference tables above first for common lookups
- Consult
references/compliance-frameworks.md for detailed requirements, the Technology Code of Practice (13 points), AI Playbook (10 principles), NHS DSPT assertion areas, UK GDPR specifics, and certification renewal schedules
- Be specific about what's mandatory vs. recommended — ISO 27001 is "strongly expected" not technically mandatory; Cyber Essentials Plus IS mandatory for handling personal data
- Consider the lot — Lot 3 (Cloud Support/consultancy) has different security expectations than Lots 1 & 2 (hosting/software)
Related Commands
These ArcKit commands generate security-related documents:
| Command |
Security Area |
/arckit:security |
Comprehensive security evidence document |
/arckit:sdd-lot1, sdd-lot2, sdd-lot3 |
Security sections within SDDs |
/arckit:declaration |
Legal compliance and exclusion grounds |
Additional Resources
Reference Files
references/compliance-frameworks.md — Complete reference covering all certifications (ISO 27001, Cyber Essentials, SOC 2, CSA STAR, PCI DSS, ISO 22301, ISO 20000-1), UK government frameworks (NCSC principles, Technology Code of Practice, AI Playbook, NHS DSPT), data protection (UK GDPR, DPA requirements), security clearances, evidence guidance, and certification renewal schedules. Consult for any detail not covered by the quick reference tables above.
1---2name: cloud-security-compliance3description: Answers a G-Cloud supplier's questions about security certifications and compliance evidence: ISO 27001, Cyber Essentials, SOC 2, CSA STAR, PCI DSS, DSPT, the NCSC 14 cloud security principles, UK GDPR and data protection, BPSS, SC and DV clearances, and what evidence a submission needs. Not needed when the request is for a security evidence document or an SDD security section; /arckit-uk-gcloud:security and the sdd-lot commands produce those.4---56# Cloud Security & Compliance78Conversational knowledge about security certifications, NCSC principles, compliance frameworks, evidence requirements, and UK government security standards relevant to G-Cloud service providers.910## Purpose1112Provide instant answers to common questions about security and compliance requirements for G-Cloud without requiring document generation. This covers certifications, frameworks, clearances, and evidence guidance.1314## When to Use1516Activate when users ask about:1718- Whether they need a specific certification (ISO 27001, Cyber Essentials, SOC 2, etc.)19- What the NCSC 14 cloud security principles are20- UK GDPR requirements for cloud services21- Security clearance levels and when they apply22- What evidence to provide (and what NOT to provide)23- Certification costs, timelines, and renewal cycles24- NHS DSPT requirements25- AI governance and the AI Playbook2627## Quick Reference: Key Certifications2829| Certification | G-Cloud Importance | Validity | Typical Cost |30|---------------|-------------------|----------|-------------|31| ISO 27001 | High — expected by most buyers | 3 years (annual surveillance) | £5K–£50K+ |32| Cyber Essentials | High — mandatory for personal data | 12 months | £300–£500 |33| Cyber Essentials Plus | High — independent verification | 12 months | £1,500–£5,000 |34| SOC 2 Type II | Medium-High — sophisticated buyers | Annual reports | £20K–£80K |35| CSA STAR | Medium — cloud-native services | Varies by level | Varies |36| PCI DSS | Required for payment processing | Annual | Varies by level |3738## Quick Reference: NCSC 14 Principles3940| # | Principle | Category |41|---|-----------|----------|42| 1 | Data in transit protection | Data Protection |43| 2 | Asset protection and resilience | Data Protection |44| 3 | Separation between users | Separation |45| 4 | Governance framework | Governance |46| 5 | Operational security | Operations |47| 6 | Personnel security | Personnel |48| 7 | Secure development | Development |49| 8 | Supply chain security | Supply Chain |50| 9 | Secure user management | Access |51| 10 | Identity and authentication | Access |52| 11 | External interface protection | Infrastructure |53| 12 | Secure service administration | Administration |54| 13 | Audit information for users | Audit |55| 14 | Secure use of the service | Usage |5657## Quick Reference: Security Clearances5859| Level | Typical Use | Timeline |60|-------|-------------|----------|61| BPSS | Standard government access | 1–2 weeks |62| CTC | Airport, defence | 6–8 weeks |63| SC | OFFICIAL-SENSITIVE data | 6–8 weeks |64| DV | SECRET classification | 6–12 months |65| eDV | TOP SECRET classification | 12+ months |6667## Quick Reference: Evidence to Provide6869| Certification | Provide | Do NOT Provide |70|---------------|---------|----------------|71| ISO 27001 | Certificate (scope must cover service) | Full audit reports |72| Cyber Essentials | Certificate with badge | Internal assessments |73| SOC 2 | Management assertion letter | Full SOC 2 report |74| CSA STAR | Registry entry link | Detailed assessment |75| NHS DSPT | Published status | Internal toolkit data |76| PCI DSS | Attestation of Compliance (AOC) | Pen test findings |7778General rule: never provide full audit reports, pen test findings, detailed vulnerability data, internal policy documents, or unredacted contracts.7980## Answering Questions8182When answering security and compliance questions:83841. **Check the quick reference tables above first** for common lookups852. **Consult `references/compliance-frameworks.md`** for detailed requirements, the Technology Code of Practice (13 points), AI Playbook (10 principles), NHS DSPT assertion areas, UK GDPR specifics, and certification renewal schedules863. **Be specific about what's mandatory vs. recommended** — ISO 27001 is "strongly expected" not technically mandatory; Cyber Essentials Plus IS mandatory for handling personal data874. **Consider the lot** — Lot 3 (Cloud Support/consultancy) has different security expectations than Lots 1 & 2 (hosting/software)8889## Related Commands9091These ArcKit commands generate security-related documents:9293| Command | Security Area |94|---------|--------------|95| `/arckit:security` | Comprehensive security evidence document |96| `/arckit:sdd-lot1`, `sdd-lot2`, `sdd-lot3` | Security sections within SDDs |97| `/arckit:declaration` | Legal compliance and exclusion grounds |9899## Additional Resources100101### Reference Files102103- **`references/compliance-frameworks.md`** — Complete reference covering all certifications (ISO 27001, Cyber Essentials, SOC 2, CSA STAR, PCI DSS, ISO 22301, ISO 20000-1), UK government frameworks (NCSC principles, Technology Code of Practice, AI Playbook, NHS DSPT), data protection (UK GDPR, DPA requirements), security clearances, evidence guidance, and certification renewal schedules. Consult for any detail not covered by the quick reference tables above.